data-protection
272 skills across 25 jurisdictions.
Skills
Conducting AI System Privacy Assessment
Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training da…
Conducting Data Protection Audit
Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Inclu…
Conducting Prior Consultation Process
Guides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirem…
Conducting Transfer Impact Assessment
Guides the post-Schrems II Transfer Impact Assessment process following EDPB Recommendations 01/2020 six-step methodology. Covers destination country…
Configuring Google Consent Mode v2
Configuring Google Consent Mode v2 for privacy-compliant measurement and advertising. Covers default and update commands, consent state mapping to GA…
Consent Audit — Einwilligungspruefung
Prueft Einwilligungs-Flows auf DSGVO-Konformitaet: DOI-Token-Ablauf, Widerruf-Workflow, Cookie-Banner
Consumer Breach Notification Letter
Drafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal informati…
Consumer Data Breach Notification Letter
Drafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produ…
Controller RoPA Creation
Creates GDPR Article 30(1) Records of Processing Activities (RoPA) for data controllers with all seven mandatory fields: controller identity and cont…
Cookie Consent Banner and Policy
Drafts publication-ready cookie policies, banner copy, and consent-flow language under GDPR/ePrivacy, CCPA/CPRA, and major U.S. state privacy laws. C…
COPPA Compliance — Children's Online Privacy Protection Act
Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including si…
Creating GDPR Remediation Roadmap
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation. Activate when building com…
Criminal Conviction and Offence Data Handling — GDPR Art. 10
Handles GDPR Art. 10 criminal conviction and offence data classification including official authority requirements, national law derogations, and com…
Critical rules
Ensure data privacy compliance covering GDPR obligations, user consent management, data retention policies, PII detection, and data anonymisation wit…
Customize – Praxisprofil anpassen
Bestehende Datenschutzdokumentation oder Richtlinien an neue Anforderungen oder Verarbeitungstätigkeiten anpassen. Art. 5 24 DSGVO Rechenschaftspflic…
customize-11
Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, esca…
Cyber Law Compliance Summary
Produces structured cyber law compliance memoranda covering GDPR, CCPA, state privacy laws, and sector-specific regulations for US and EU operations.…
Data Breach Notification Letter
Drafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG require…
Data Inventory and Mapping for Classification
Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, thir…
Data Retention and Destruction Policy
Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protoco…
Data Subject Rights for AI Systems
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model…
data-privacy-agreement
Draft and fill data privacy agreement templates — DPA, data processing agreement, GDPR, HIPAA BAA, business associate agreement, AI addendum. Produce…
Datenpannen-Meldung (Art. 33/34 DSGVO)
Datenpanne nach Art. 33 34 DSGVO melden wenn Sicherheitsverletzung personenbezogener Daten vorliegt. Art. 33 34 DSGVO Meldepflichten § 65 BDSG. Prüfr…
Datenschutz-Folgenabschätzung
Datenschutz-Folgenabschaetzung DSFA nach Art. 35 DSGVO bei voraussichtlich hohem Risiko. Anwendungsfall neues Verarbeitungsverfahren mit hohem Risiko…
data-protection legal skills by jurisdiction
Data protection work is defined by the tension between rapidly evolving regulatory requirements and the need for consistent, jurisdiction-specific compliance — a DPA investigation in Germany, a cross-border data transfer impact assessment under the GDPR, and a breach notification to a national authority each demand a different set of steps, timelines, and substantive rules. The data protection legal skills assembled in the ThomasMore catalog address that breadth: drafting privacy notices and data processing agreements, mapping lawful bases for processing, conducting data protection impact assessments, and building incident response workflows across dozens of regulatory regimes. Every skill is agent-ready, meaning an AI agent can execute the underlying task — running over MCP or downloaded as a file — without requiring practitioners to rebuild the logic from scratch for each matter.
Coverage spans frameworks from the GDPR and its national implementation laws through sector-specific and regional regimes, reflecting the reality that a single multinational client may face overlapping obligations across Europe, Asia-Pacific, Latin America, and beyond. Authors maintain these skills as regulators update guidance, adequacy decisions shift, and enforcement priorities change, so the catalog reflects current standards rather than yesterday's rules. The collection is useful across the full spectrum of advisory work — counsel advising data controllers or processors, those handling regulatory investigations, and those advising on international data flows will each find targeted capabilities here. Filter by jurisdiction to bring the right regulatory framework into focus for the matter in front of you.